A HYBRID DEEP LEARNING APPROACH FOR ACCURATE SECURITY REQUIREMENTS CLASSIFICATION USING SEMANTIC AND STATISTICAL FEATURE INTEGRATION
Abstract
Security requirements classification is a fundamental task in requirements engineering, enabling software engineers to discover security-related requirements during the early stages of the SDLC. In large software development projects, the identification of Security Requirements is time-consuming, and error-prone. In this regard, this research aims to address this challenge by proposing a hybrid model of CNN and XGBoost for automated binary classification of Security and Non-Security Requirements. The proposed framework uses a neural network for deep feature refinement, and the final classification is performed using XGBoost. To capture the semantic information and the statistical information of the text, SBERT embeddings are combined with TF-IDF representations before feature refinement. The proposed framework is assessed with the publicly available PROMISE dataset by analyzing its accuracy, precision, recall, F1-score and AUC-ROC. Experimental results show that the proposed model brings 93% accuracy, 84% precision, 88% recall, 86% F1-score and 99% AUC-ROC, outperforming previous state-of-the-art approaches for security requirements classification. The results show that the proposed hybrid framework is an effective and reliable solution for automated security requirements classification and reduces manual effort and supports intelligent software requirements engineering.












